This issue was fixed in a patch to version 6.8 published on 15.05.2026, deployments without this patch are still vulnerable.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 29 May 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Opensolution
Opensolution quick.cms |
|
| Vendors & Products |
Opensolution
Opensolution quick.cms |
|
| Metrics |
ssvc
|
Fri, 29 May 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | QuickCMS is vulnerable to Cross-Site Scripting (XSS) through its insecure HTTP-based plugin‑fetching mechanism. A malicious attacker can perform a Man‑in‑the‑Middle (MITM) attack by impersonating the opensolution.org server and serving arbitrary HTML or JavaScript at the plugin list endpoint. When a user accesses the plugin page, the malicious content is automatically fetched, rendered, and executed. This issue was fixed in a patch to version 6.8 published on 15.05.2026, deployments without this patch are still vulnerable. | |
| Title | XSS in QuickCMS | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CERT-PL
Published:
Updated: 2026-05-29T17:31:36.344Z
Reserved: 2026-03-19T10:45:47.736Z
Link: CVE-2026-33386
Updated: 2026-05-29T17:31:32.731Z
Status : Deferred
Published: 2026-05-29T16:16:25.560
Modified: 2026-05-29T16:29:11.350
Link: CVE-2026-33386
No data.
OpenCVE Enrichment
Updated: 2026-05-29T19:15:05Z